Cloud Encryption deployment for VMware-based application services

cloud keyboard

As the infrastructure cloud market (IaaS and PaaS) continues to grow rapidly, we are seeing quite a few customers who are delivering an application – whether it is a mission-critical or SaaS application – and basing their solution on VMware. Some of these are deploying VMware in their private data center, while others are leveraging [...]

Cloud providers: Adopt a cloud encryption “profit center” approach

Cloud encryption for cloud providers

I was recently involved in some interesting discussions around cloud encryption as an added value service for IaaS and DRaaS service providers.  According to the service providers we’ve talked with, data encryption is critical for compliance oriented customers, as well as for ISVs’ deploying their software as a service offering on an Infrastructure cloud. While [...]

Cloud Key Management and Oracle TDE

Encryption is key

Encryption of databases is a must for compliance, privacy and security. The major databases have built-in encryption capabilities. Specifically, Oracle has a built-in Transparent Data Encryption capability. As cloud computing evolves, these features are being used to try and create secure cloud database solutions enjoying cloud encryption. TDE is a basic building block for such [...]

Cloud security and the omnibus HIPAA – Thoughts on compliance and the shared responsibility model

The new and enhanced HIPAA omnibus standard brings an interesting question with regards to cloud security and the shared responsibility model in IaaS clouds. Since the release of the HIPAA omnibus, we’ve received many questions around “BAA” agreements, and how the responsibility split actually happens between (for example) the cloud provider and an ISV providing a healthcare [...]

Using the Porticor Agent

The Porticor Agent enables you to encrypt disks on your server, using Porticor’s highly secure key management technology. The Agent connects to a key management appliance – a Porticor virtual machine deployed in your cloud account, which is responsible to safeguard your master key so that you do not have to trust anybody else with [...]

Cloud Compliance in Infrastructure as a Service is Mainly Your Responsibility

Level of control

Cloud compliance is always a hot topic, but recent updates to the HIPAA and PCI regulations, have further enhanced the need to clarify some important points around cloud compliance and regulatory compliance. In this blog post, I would like to address some issues as highlighted in the valuable PCI DSS Cloud Computing Guidelines (available here), [...]

Key management and encryption in VMware-based clouds

VMware is without a doubt a major platform for private as well as public cloud deployments. But as in any other cloud-based system, data security, and more specifically cloud encryption and key management are fundamental building blocks. Cloud key management and encryption requirements We have found that external users have many of the same security [...]